Malware.View on attack.mitre.org
MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.
| Technique | Procedure example |
|---|---|
| T1074.001 Local Data Staging |
MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`. |
| T1552.006 Group Policy Preferences |
MirrorStealer can target Group Policy Preferences for credentials. |
| T1555 Credentials from Password Stores |
MirrorStealer has the ability to steal credentials from email clients. |
| T1555.003 Credentials from Web Browsers |
MirrorStealer can steal credentials stored in browsers. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.